AI for South Africa

Starting Your AI Journey in Business

Maximillion Digital Season 1 Episode 5

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 19:19

Before your business rushes into AI tools, there are a few important foundations to put in place.

In this episode of AI for South Africa, Maxine talks about what businesses need to understand before AI becomes part of everyday work. It is not just about choosing ChatGPT, Copilot, Gemini, Claude, or any other tool. It is about making sure your team knows what is allowed, what data is safe to share, and who is responsible for the final output.

We look at four key areas every business should consider:

AI governance policies
 Data sovereignty and POPIA responsibilities
 Shadow AI in the workplace
 Choosing the right AI tools for your business

Whether you are a small business owner, a manager, or part of a larger corporate team, this episode gives you a practical starting point for using AI safely, responsibly, and with proper guardrails.

Your action for the week: find out whether your business has an AI policy that covers the tools your team is already using.

Send us Fan Mail

Max. This is AI for South Africa. Let's go. Hello again, and this is AI for South Africa, and I am Maxine. Welcome to the show. Let me paint a picture for you. A business decides to start using AI and MD or the top-notch guy gives the green light, and someone in the team sets up a Chat GPT account, and people start using it for emails and proposals and for summaries, and things feel faster. They feel excited. They use it for different things. But then three months later, someone asks, wait, what are we actually putting into this thing? What data is that? Did anybody check the privacy policy? What are our clients saying? Are we allowed to do this? Does everyone know what tools everybody is using? What's going on? And then there's silence. Nobody knows. That scenario isn't rare. It's the norm. And it's not because the people involved didn't care. It's just because nobody told them there's things to sort out before you start using these tools. Nobody helped them build the foundation within their business. And that's what we're going to discover today. We're not just talking about which A tools are best for your business. We're not doing a feature comparison today. We're talking about what a business or what your business, whether you're a five staff person or five hundred staff person, needs to understand and put into place before AI becomes real, sustainable part of your business. The four things that we need to consider. And the order matters as well, because the last thing you want to do is pick a tool before you start sorting things out. And that's exactly where businesses land up in trouble. So let's get into it. Part one. Your governing policies. This is a good place to start because this is the thing that most businesses skip. It's the thing that causes the most problems. Before a business starts using AI in any meaningful way, you need a governing policy. It does sound a little bit corporate-y, but not everybody reads it. I'm not talking about like a 55-page manual. I'm just talking about clear steps, set of rules, answers to questions if anybody has them before the trouble sets in. Here's why this is the starting point. In 2025, an enterprise report found that 68% of employees were already using free tier tools through their personal accounts at work, and 57 of them were entering sensitive business data into these tools. That's more than half. That's not fringe behavior. That's happening inside everybody's business right now, whether you know about it or whether you don't. The governing policy closes that gap. It doesn't have to be long, it just has to be clear. You have to have the rules. At minimum, you need four things. One, what tools are approved. Two, what can and can't go into those tools. Three, who is accountable for the AI output? Four, how do you disclose the use of AI to your customers or the people you work with? For SMME owners, this doesn't need to be a formal or fancy thing. You can include it in your privacy policy on your website. It can be in plain English, and you can just discuss it with your team and maybe your customers if it affects your customers. For corporate teams, if your organization doesn't have an AI policy number one or a privacy policy, that's the first place to start and raise it with your leadership. If one exists, that's perfect, but it needs to start communicating what the gap is and where these elements misfit. The second part is data sovereignty. So what does that mean? So data sovereignty is one of those phrases that sounds very technical, but you'll know about it as soon as something goes wrong. Let me break it down simply. Data sovereignty is about where your business data lives, who controls it, and which countries laws apply. So when your team types something into AI, let's say a client brief or financial projections or report that's needed, the information goes and sits somewhere. It goes to a server. Where does that server belong? That server belongs to a company, but where is that company sitting? It's probably not in South Africa. And the laws that govern what happens to that data on that server depends on where it physically sits. Most of AI tools are run by American and European countries. Their infrastructure is offshore, which means the data your business puts into those tools is sitting outside of South Africa, which means a different legal framework needs to apply. So even though South Africa doesn't have an AI law policy in place, it doesn't mean you don't follow the rules. It means that you need to follow American and European laws because your data actually sits in their territory. Now, because of Poppy, your business is responsible for personal information that you hold. That responsibility doesn't end when you pass the information into an AR tool. If you're sending that personal information, clients' details, employees' records, whatever it is, anything that can identify somebody into those AR tools and it sits in foreign service, you need to be able to be accountable for that and need to understand what happens to that data. So here's the uncomfortable truth. Knowing about this isn't the same as being protected. In a 2026 survey, they found that 44% of organizations described themselves as well informed about data sovereignty. But one in three of those same organizations still experienced a data incident. Which means they understand the concept, but they didn't have the right controls in place when something went wrong. So what does this mean practically for your business? You need to define what counts as sensitive data in your context. You need to default to anonymizing in any free tools if you don't have permission to use the data. Know which tier of tool you're using. Most enterprise and subscription tools have stronger data protection. For businesses and financial services, healthcare, or even government, um, set the bar high of what can be shared because those spaces are usually the ones where there's the most trouble. For the rest of us, you need to ask yourself this. Would you put this information on a park bench for anybody to pick up? Would you put your ID on a park bench? No, you wouldn't. Would you put all your customer information on a park bench? No, you wouldn't. So if you can answer that question, that's kind of how you must use your data. As much as I'm all for free tools, I do think that paid tools come in handy when you have sensitive data that you need to share. Another one to keep in mind is if you do have sensitive data that you want to ask AI about, a great tool to use is Notebook LM because it does have a window ring fence around the chat that you're having. Part three Shadow AI. Okay, so what is shadow AI? Shadow AI is what happens when employees use tools inside of a business without the knowledge or approval of people responsible for it. So for the IT, maybe the risk or policy departments. It's not necessarily deliberate, it's not necessarily malicious. It's just usually when people are finding the tools are helping them and they're using them because no one told them not to, or there's no rules and regulations around what they can or can't do. And the scale of this is bigger than what most people realize. One survey found that 92% of organizations are concerned about a shadow AI. So they know that it happens, and yet only 14% of them have put controls into place to address this so that it doesn't happen. So everyone's aware of it. They're just acting like an ostrich and sticking their head in the ground and hoping that nothing's gonna change or hoping that nothing's gonna happen. There's a gap there between the worry and the action is where most people are sitting right now. And honestly, it's usually not laziness, it's about no one really knows where to start. Think about what actually happens on the ground in a typical business. The HR manager started using free AI tools to draft job descriptions and performance reviews. The sales team is summarizing client calls using browser extensions they found. Someone in finance is using personal chat GPT accounts to help them build reports because it's faster. None of them told IT or none of them checked to see the data policy. None of them were told not to do it because there is no policy to that point. The risk here isn't just a security risk, even though it's real, it's also a consistency risk, a quality risk, a liability risk. If different parts of the business are using different tools and different data handling standards, you have no way to manage what's happening under the business name. So what happens when shadow AI isn't addressed? Sensitive business information like client data, internal financials, unreleased product plans ends up in tools that businesses never approve and can't audit. If it's a free tool, then it's out to the public. If there's ever a breach or complaint or legal question, you can't account for it because it's not in one place. You don't know what happened, you don't know where it was sitting. AI generated content goes out without proper review because no one knew it was AI generated. That becomes a quality problem. When the business eventually tries to standardize the AI use, it's fighting against deeply embedded habits. Um, it's already spread across the organization. So it's much harder to course correct that way. So, what do we need to do about this? The first thing is audit first before you try and fix anything, find out exactly what's happening, then create a clear approved path that everybody understands. You need to communicate that policy, not just write it down. You send emails, have a meeting, tell everybody about it, and make sure it's safe to ask questions. So make an environment where there's no judgment, it's about okay, you did do this previously, but now this is how we're doing it now. Having that openness will create consistency, having that openness will allow everyone to be on your path. So, part four. What tools should we actually use? Right, we've hit the foundation, we have governance in place, we've set down the boundaries, and the shadow AI is under control. Now we can talk about what tools are allowed. The conversation is a lot easier this way because we understand where the restrictions are. The smartest starting point for all businesses is to go with AI that's already embedded in software that they're paying for. So, what do I mean by that? If your business is running on Microsoft, then Microsoft Copilot would be a perfect starting point. It's not a separate tool, it's bolted onto everything already, it's less friction, it's less onboarding, and importantly, it sits inside of your licensing and compliance structure already. If your business sits in Google ecosystem, like Gmail and Google Workspace, then Google Gemini would apply the same way. If you're not in any of those ecosystems and you want a standalone AI assistant for more general use, like drafting, research, content, problem solving, then tools like Claude or ChatGPT are both strong options. Both of these have business and enterprise tiers with stronger data protections than the free consumer version. Here's the key principle: don't let every department or individual choose their own tool independently. That's how you end up with 12 different AI tools running across your business with no visibility and no control. Start with one approved tool, make it official, give people education, give them a clear path of where to go, and then you can always expand from there. But only do that once the foundation is in place. Let's bring this to real life examples. Okay, so an SMME, Tundi's bookkeeping. Tandy runs a small bookkeeping practice in Pretoria with herself and two part-time staff. She decides her business is going to start with AI and to help the clients communicate and document drafting. Before she opens a single AI tool, she does three things. She writes on a page how the company will use AI, noting what they can and can't do with it. Okay. She then has a 30-minute conversation with her staff, understanding the rules and understanding what they can and can't do with it. And then she decides after the fact, based on that, that she's going to use Chat GTP Plus because their TAID version is stronger with data protection. The rule is simple: no client names, no client numbers, no tax reference numbers are allowed in the AI tools. And anonymized figures when dropping them into the tools. Anything client-specific gets reviewed by her before it goes out. So she had a policy, she had a conversation, she had a tool, and then that was it. Her system was set in place and everybody understood what they could and couldn't do. Same pot, just a larger business. It's a financial firm in Sanson. They had 80 staff across Operation, Compliance, Sales, and Finance. The IT manager noticed that at least a dozen employees were running a various AI tools, some free, some paid. Um, but the IT department didn't approve it. Rather than banning everything, because that's not going to help anybody, he decided to work with compliance to build a simple AI governance framework. And how they did that was they actually just extended their current poppy governance document. They defined what can and can't go into the AI tools, they identified that Microsoft Copilot was their approved tool because they were already in that environment, and then they actually ran a company-wide briefing session. They also created a simple process for staff to flag any new tools that they wanted to use. So the shadow AI didn't disappear immediately, but the team slowly but surely moved to co-pilot as time went by. So you can see even small businesses with three people and large corporations kind of have the same needs when it comes to these elements. It doesn't take a lot of time. You can even use AI to help you draft the policies. Just put in what you want, what you don't want, what you do, and suggested things that you need to include and put it in a place where your staff and your clients, if your AI touches your clients, can view it. So your one action for this week is I want you to find out if your business has an AI governing policy, specifically one that covers AI tools. If you are the person who decides this, then I would say get started. Have the conversation with your staff, see what's happening, what tools they're using, and start to put these guardrails up. Remember, AI does well with guardrails. Think of it as the bowling alley. It's a lot easier to do things correctly. Hit that target that needs to be hit with the guardrails up than with them down. The best foundation is to put these elements into place from the beginning or as soon as you can. When you knee deep trying to go backwards, it's a struggle. It might not be glamorous to do this, but it's the difference between AI that adds value or the AI that adds risk. Next week we're going to dive into a conversation with someone who has had formal training through Helplink, where she is now and how AI has helped her from a small business perspective and see where we can take some learnings from her. And if there's something from today's episode that landed for you, share it with the person who needs to hear it. I am Maxine, and this is AI for South Africa. Let's go back to the bottom. Over Cape Town, a disarming. A different kind of tree.